Splunk Search

How to create graph based on Std deviation & Avg

jaibalaraman
Path Finder

Hi 

Can anyoine suggest me how to create Avg & Std Dev graph from the fields

 

jaibalaraman_0-1712025787892.png

 

Labels (1)
Tags (1)
0 Karma

jaibalaraman
Path Finder

Hi Kendall 

yes i tried that, stil not getting any output 

jaibalaraman_0-1712027466637.png

 

0 Karma

KendallW
Communicator

Add a space between  the two timechart functions. E.g. 

| timechart avg(event.Properties.duration) stdev(event.Properties.duration)

Also, you can remove the 

| iplocation

 as we aren't using any of the fields that command adds for this visualization, so it will only slow down the search.

0 Karma

tscroggins
Influencer

Hi @jaibalaraman,

You can calculate the mean and standard deviation using the stats command:

| stats avg(event.Properties.duration) as u stdev(event.Properties.duration) as s

however, that won't produce a chart.

At a glance, your data is not normally distributed. You can generate a simple histogram with the chart command:

| chart count over event.Properties.duration span=31

If you have Splunk Machine Learning Toolkit installed, you can use the histogram macro and visualization:

| `histogram("event.Properties.duration", 31)`

Note that the histogram macro uses the bin command:

bin "$var$" bins=$bins$ | stats count by "$var$" | makecontinuous "$var$" | fillnull count

It won't necessarily honor your bin count.

What type of graph or visualization would you like to create?

0 Karma

jaibalaraman
Path Finder

The below 2 commands are not working 

| `histogram("event.Properties.duration", 31)`

bin "$var$" bins=$bins$ | stats count by "$var$" | makecontinuous "$var$" | fillnull count

 

What type of graph or visualization would you like to create?

Just want to create a dashboard tile to show the metric 

0 Karma

KendallW
Communicator

Hi @jaibalaraman try this

. . . | timechart avg(event.Properties.duration) stdev(event.Properties.duration)
0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...